The InformationWeek -- Blogs
Over The Air

Topics:   Mobile

  • Email this page E-mail this page
  • Print this page Print this page
  • Bookmark and Share
  • icon

Study: NYC Retailers Not Protecting Wireless Networks


Posted by Eric Zeman, Jan 14, 2008 11:19 AM

Security company AirDefense recently surveyed the retail scene in all five NYC boroughs and determined that wireless security is lax just about everywhere. Fully 39% of access points in retail environments were completely unprotected, and 29% use only WEP encryption. That's your data that's not being protected. Listen up, NYC retailers: If you want my business, protect my info.


It appears that the dangers of open wireless networks haven't been adequately communicated to NYC-area retailers. The results of AirDefense's survey are nothing short of amazing:

During its monitoring, AirDefense discovered more than 1,300 Access Points. Alarmingly, 39% were unencrypted, with 29% encrypted with Wired Equivalent Privacy (WEP), the weakest protocol for wireless data encryption, which can be compromised in minutes but is in wide use today. In addition, it was found that others were utilizing Wi-Fi Protected Access (WPA) or WPA2, the two strongest encryption protocols for prevention against theft.

AirDefense conducted monitoring in some of the busiest retail locations within the five boroughs of NYC. AirDefense discovered numerous wireless vulnerabilities due to data leakage, rogue devices, mis-configured Access Points, poorly named Access Points, and outdated Access Point firmware utilized by large retail chains. Many retailers didn't simply follow basic security practices. This type of "cookie cutter" approach occurs when large retailers with multiple locations within NYC and/or nationwide use the same technology in all retail locations, so vulnerabilities will repeat themselves across the entire store chain.

AirDefense also found 35% of Service Set Identification (SSIDs) had the store name in the SSID, giving away retailers' identities. SSIDs can easily be reconfigured, but often times are not. AirDefense found an unexpected upswing in rogue devices which might be attributed to the type of locations surveyed ,as there was a broad focus on shopping areas with heavy consumer day-to-day use versus flagship tourist destinations where remote chains might have been overlooked by retailers. AirDefense also found point-of-sale devices advertising themselves over the wireless network. This, combined with the most recent operating system vulnerabilities, could lead to an easy compromise of the devices, as well as unauthorized credit card and consumer information obtained.

Additionally, some of the networks discovered were fresh out of the box, using default configurations and SSIDs, such as retail wireless, POS Wi-Fi, company name, or store#1234. This sends out a signal to someone with a desire to commit fraud that nothing has been changed on these devices and the entire wireless network.

I could possibly forgive some small, local businesses for not being up to speed on the threats of wireless technology. But the IT managers for any national chain shown to be compromising both the company's and customers' data should be scolded sternly.

I just decided to perform an unscientific study. I am working in a Starbucks today. From where I am sitting, I can see five Wi-Fi networks, including the one in Starbucks, and one around the corner in Panera. To access the Starbucks network, you have to have an account with T-Mobile. The Panera network is a public hotspot. The other three belong to national retail chains. Two of them are WPA protected. The third is free and clear.

This isn't good enough, people.

« Now Lenovo Loads Linux, Too | Main | Microsoft's Beta Download Center: Bigger, Prettier, And Slower »



Sign Up Now
For InformationWeek News Alerts




This is a public forum. United Business Media and its affiliates are not responsible for and do not control what is posted herein. United Business Media makes no warranties or guarantees concerning any advice dispensed by its staff members or readers.

Community standards in this comment area do not permit hate language, excessive profanity, or other patently offensive language. Please be aware that all information posted to this comment area becomes the property of United Business Media LLC and may be edited and republished in print or electronic format as outlined in United Business Media's Terms of Service.

Important Note: This comment area is NOT intended for commercial messages or solicitations of business.




 
Mobile Video


Sign Up For The Over The Air Newsletter
Every Friday, our experts and analysts explore the business, strategy, and management issues most important to mobile and wireless technology.

Sign up for our free, weekly newsletter today!

Newsletter Archives


 

  1. Sequential Programming: Like Eating Peas with a Straw.
  2. Biomolecular device using self-assembled DNA nanostructures?
  3. Coreinfo v2.0: A Simple Utility to Understand the Manycore Complexity in Windows


Join The InformationWeek Group On LinkedIn


                           


  1. More Reasons Why Linux Misses The Desktop
  2. Too Much Netbook For Too Litl?
  3. Motorola Explains Why Droid Doesn't Have Multi-Touch
  4. Sprint And T-Mobile Headed The Wrong Direction


  1. Hadoop Crunches Web-Sized Data
  2. Microsoft Acquires SourceGear's Teamprise Unit
  3. Gartner Downgrades SaaS Forecast
  4. Google To Acquire AdMob
  5. RIM Boosts BlackBerry Developer Tools
  6. Microsoft: Windows 7 Malware Threat 'Sensationalized'

 

  Ars Technica
Boing Boing
Channel 9 Forums
CRN Blogs
Dr.Dobb's Portal: Blogs
Engadget
Gizmodo
GrokLaw
  Lifehacker
Schneier on Security
Slashdot
TechCrunch
Techdirt
Techmeme
Valleywag

  DECEMBER 2008
NOVEMBER 2008
OCTOBER 2008
SEPTEMBER 2008
AUGUST 2008
JULY 2008
JUNE 2008
MAY 2008
  APRIL 2008
MARCH 2008
FEBRUARY 2008
JANUARY 2008
DECEMBER 2007
NOVEMBER 2007
OCTOBER 2007
SEPTEMBER 2007